Skip to content

Commit

Permalink
Ingest OSV - Cloud Storage
Browse files Browse the repository at this point in the history
  • Loading branch information
github-actions committed Dec 21, 2024
1 parent a8021b2 commit 1496e62
Show file tree
Hide file tree
Showing 5 changed files with 169 additions and 1 deletion.
2 changes: 1 addition & 1 deletion config/start-keys.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
ossf-package-analysis:
confident/: confident/20241220/195550-npm-kubernetes-jobs-javascript-69.0.0.json
confident/: confident/20241220/222206-npm-testbyakash2310xxxxxxxnowaympasti-69.0.0.json
reversing-labs:
RLMA-: RLMA-2024-11212.json
RLUA-: RLUA-2024-11114.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
{
"modified": "2024-12-21T09:50:39Z",
"published": "2024-12-21T09:50:39Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in aauto-assign-team-action (npm)",
"details": "The OpenSSF Package Analysis project identified 'aauto-assign-team-action' @ 0.1.1 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "aauto-assign-team-action"
},
"versions": [
"0.1.1"
]
}
],
"credits": [
{
"name": "OpenSSF: Package Analysis",
"type": "FINDER",
"contact": [
"https://github.com/ossf/package-analysis",
"https://openssf.slack.com/channels/package_analysis"
]
}
],
"database_specific": {
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"sha256": "20d6b8df49c8a196bdddfe3670a09617033a86639fe61a4a191ae4f3dc926715",
"import_time": "2024-12-21T10:05:14.646637162Z",
"modified_time": "2024-12-21T09:50:39Z",
"versions": [
"0.1.1"
]
}
]
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
{
"modified": "2024-12-21T09:47:36Z",
"published": "2024-12-21T09:47:36Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in aauto-assign-team-action (npm)",
"details": "The OpenSSF Package Analysis project identified 'aauto-assign-team-action' @ 0.1.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "aauto-assign-team-action"
},
"versions": [
"0.1.0"
]
}
],
"credits": [
{
"name": "OpenSSF: Package Analysis",
"type": "FINDER",
"contact": [
"https://github.com/ossf/package-analysis",
"https://openssf.slack.com/channels/package_analysis"
]
}
],
"database_specific": {
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"sha256": "24334b1015df570a4828e5982d0285375f64bb4a889f3c54431ba385b54f0a27",
"import_time": "2024-12-21T10:05:14.569236354Z",
"modified_time": "2024-12-21T09:47:36Z",
"versions": [
"0.1.0"
]
}
]
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
{
"modified": "2024-12-21T09:42:28Z",
"published": "2024-12-21T09:42:28Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in auto-assign-team-actionn (npm)",
"details": "The OpenSSF Package Analysis project identified 'auto-assign-team-actionn' @ 0.1.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n\n- The package executes one or more commands associated with malicious behavior.\n",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "auto-assign-team-actionn"
},
"versions": [
"0.1.0"
]
}
],
"credits": [
{
"name": "OpenSSF: Package Analysis",
"type": "FINDER",
"contact": [
"https://github.com/ossf/package-analysis",
"https://openssf.slack.com/channels/package_analysis"
]
}
],
"database_specific": {
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"sha256": "0a76c2ee75baa7c330f6245cd32f36ea9ab50a438b5ae22970e6280a498a5236",
"import_time": "2024-12-21T10:05:14.494370046Z",
"modified_time": "2024-12-21T09:42:28Z",
"versions": [
"0.1.0"
]
}
]
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
{
"modified": "2024-12-21T10:00:58Z",
"published": "2024-12-21T10:00:58Z",
"schema_version": "1.5.0",
"id": "",
"summary": "Malicious code in cosmos-hub-docs-site (npm)",
"details": "The OpenSSF Package Analysis project identified 'cosmos-hub-docs-site' @ 2.0.0 (npm) as malicious.\n\nIt is considered malicious because:\n\n- The package communicates with a domain associated with malicious activity.\n",
"affected": [
{
"package": {
"ecosystem": "npm",
"name": "cosmos-hub-docs-site"
},
"versions": [
"2.0.0"
]
}
],
"credits": [
{
"name": "OpenSSF: Package Analysis",
"type": "FINDER",
"contact": [
"https://github.com/ossf/package-analysis",
"https://openssf.slack.com/channels/package_analysis"
]
}
],
"database_specific": {
"malicious-packages-origins": [
{
"source": "ossf-package-analysis",
"sha256": "a34cccaa0f1542346f9bde458f8b0160dfc0e0d1d8718d8acc264d706162d8a3",
"import_time": "2024-12-21T10:05:14.728230572Z",
"modified_time": "2024-12-21T10:00:58Z",
"versions": [
"2.0.0"
]
}
]
}
}

0 comments on commit 1496e62

Please sign in to comment.